stdlib has 17 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 5 in the last 90 days against 3 in the 90 before. The busiest recent month was August 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 3
Weakness classes
Products
- stdlib 17
Worst active — by depth score
CVE-2026-56858High· 8.1Fix Javascript regexp context tracking in html/template45CVE-2026-56862High· 7.5Limit handshake messages we are willing to accept post-handshake in crypto/tls41CVE-2026-56860High· 7.5Avoid quadratic complexity in resolvePath in net/url41CVE-2026-56859High· 7.5Add recursion depth guard during decode in encoding/xml41CVE-2026-33818High· 7.5Enforce maximum recursion depth in encoding/asn141
stdlib vulnerabilities
CVEs affecting stdlib, newest first. Open any entry for full detail, references, and exploit status.
17 CVEsRSS
CVE-2026-56860High· 7.5Avoid quadratic complexity in resolvePath in net/url
Avoid quadratic complexity in resolvePath in net/url
CVE-2026-56858High· 8.1Fix Javascript regexp context tracking in html/template
Fix Javascript regexp context tracking in html/template
CVE-2026-56862High· 7.5Limit handshake messages we are willing to accept post-handshake in crypto/tls
Limit handshake messages we are willing to accept post-handshake in crypto/tls
CVE-2026-56859High· 7.5Add recursion depth guard during decode in encoding/xml
Add recursion depth guard during decode in encoding/xml
CVE-2026-33818High· 7.5Enforce maximum recursion depth in encoding/asn1
Enforce maximum recursion depth in encoding/asn1
CVE-2026-42504High· 7.5Quadratic complexity in WordDecoder.DecodeHeader in mime
Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-39836NonePanic in Dial and LookupPort when handling NUL byte on Windows in net
Panic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-32281Medium· 5.9Inefficient policy validation in crypto/x509
Inefficient policy validation in crypto/x509
CVE-2025-68121NoneUnexpected session resumption in crypto/tls
Unexpected session resumption in crypto/tls
CVE-2025-61728NoneExcessive CPU consumption when building archive index in archive/zip
Excessive CPU consumption when building archive index in archive/zip
CVE-2025-61729NoneExcessive resource consumption when printing error string for host certificate validation in crypto/x509
Excessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-58183NoneUnbounded allocation when parsing GNU sparse map in archive/tar
Unbounded allocation when parsing GNU sparse map in archive/tar
CVE-2024-34158NoneStack exhaustion in Parse in go/build/constraint
Stack exhaustion in Parse in go/build/constraint
CVE-2022-41715NoneMemory exhaustion when compiling regular expressions in regexp/syntax
Memory exhaustion when compiling regular expressions in regexp/syntax
CVE-2022-2880NoneIncorrect sanitization of forwarded query parameters in net/http/httputil
Incorrect sanitization of forwarded query parameters in net/http/httputil
CVE-2022-2879NoneUnbounded memory consumption when reading headers in archive/tar
Unbounded memory consumption when reading headers in archive/tar
CVE-2022-32190NoneFailure to strip relative path components in net/url
Failure to strip relative path components in net/url